Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
76.008 exploits
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALsob ataqueransomware09 jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM09 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC3
Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability
CVE-2025-24071MEDIUM09 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM09 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
CVE-2025-32756: NSE Scanning for RCE in vulnerable FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera nodes
CVE-2025-32756CRITICALsob ataque09 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHsob ataque09 jun 2025
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC1
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
CVE-2024-10914CRITICAL09 jun 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
Exploit-DB
ProSSHD 1.2 20090726 - Denial of Service (DoS)
CVE-2024-0725MEDIUMremotewindows09 jun 2025
ProSSHD denial of service
33RISCO
abrir
GitHub PoC
Arshit01/CVE-2023-20198
CVE-2023-20198CRITICALsob ataque09 jun 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALsob ataque09 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
GitHub PoC
Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)
CVE-2022-26134CRITICALsob ataqueransomware09 jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHsob ataque09 jun 2025
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC
PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins, extracting SYSTEM and SAM hives for local NTLM hashes.
CVE-2021-36934HIGHsob ataque09 jun 2025
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
Exploit-DB
TightVNC 2.8.83 - Control Pipe Manipulation
CVE-2024-42049CRITICALlocalmultiple09 jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL09 jun 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-2539HIGH09 jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49619HIGH09 jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALsob ataque09 jun 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL09 jun 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2021-3156-Exploit-Demo
CVE-2021-3156HIGHsob ataque09 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
Exploit-DB
Laravel Pulse 1.3.1 - Arbitrary Code Injection
CVE-2024-55661HIGHwebappsphp09 jun 2025
Laravel Pulse Allows Remote Code Execution via Unprotected Query Method
46RISCO
abrir
GitHub PoC1
CVE-2025-29927 - Critical Security Vulnerability in Next.js
CVE-2025-29972CRITICAL09 jun 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RISCO
abrir
GitHub PoC
CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc
CVE-2024-40453CRITICAL08 jun 2025
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the com
48RISCO
abrir
GitHub PoC
CyberBibs/Event-ID-263-Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-
CVE-2024-24919HIGHsob ataqueransomware08 jun 2025
Information disclosure
100RISCO
abrir
GitHub PoC
binneko/CVE-2025-46041
CVE-2025-46041MEDIUM08 jun 2025
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript
33RISCO
abrir
GitHub PoC1
Songul-Kizilay/CVE-2014-0346
CVE-2014-034608 jun 2025
20RISCO
abrir
Metasploit300
Listmonk Insecure Sprig Template Functions Environment Disclosure
CVE-2025-49136CRITICAL08 jun 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
43RISCO
abrir
GitHub PoC
CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-
CVE-2024-3400CRITICALsob ataqueransomware08 jun 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM08 jun 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
GitHub PoC
CVE-2025-0282
CVE-2025-0282CRITICALsob ataqueransomware08 jun 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
anteriorpágina 253 / 2.534próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.